Adobe patches flaw in LiveCycle Data Services

Adobe released a hotfix for LiveCycle Data Services that patches a vulnerability that could result in information being disclosed.

A hotfix released by Adobe on Tuesday addresses a vulnerability (CVE-2015-3269) in LiveCycle Data Services that could lead to information being disclosed.

The updated versions are 4.7.0.354169, 4.6.2.354169, 4.5.1.354169, and 3.0.0.354170 for Windows, Macintosh and Unix. Adobe rates the fix as a priority 3 update, which means the company recommends administrators install the update at their discretion. Priority 1 and 2 rated patches require faster action.

The vulnerability is associated with parsing crafted XML entities, which could lead to information being disclosed, Adobe said on its site.

“We are not currently aware of any reports of this vulnerability being exploited,” Adobe spokesperson Erika Strong told SCMagazine.com Tuesday in an email correspondence. “This issue was responsibly disclosed to Adobe.”

Adobe credited Matthias Kaiser of Code White for bringing the issue to the company's attention.

Techscape is SC Media’s content marketing platform. Industry experts share their views in the following categories

Partner Content is sponsored content brought to you by a vendor

SC Media arms cybersecurity professionals with the in-depth, unbiased business and technical information they need to tackle the countless security challenges they face and establish risk management and compliance postures that underpin overall business strategies.